Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · flowscope.com

flowscope

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-08-21
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

Exhibit A · Privacy Policy · verbatim

Flowscope uses third-party large-language-model providers to generate workflow summaries, process analyses, and related outputs. We currently use OpenAI and may add or substitute other providers over time. We use paid business API tiers from these providers. Per the applicable terms of these tiers, data submitted to the API is not used to train the

highest-risk verified finding on training use — tap for the citation
66 verified findings7 policy surfaces1/1 core docs verified

Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.

Risk triage

Watch: subprocessors data sharing

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
2
medium
3
low
1/1
docs
Trains on your data?
No training on your content by default
from 1 cited finding
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what flowscope's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Partially verifiedWorkflow & Automation

Partially verified — Privacy Policy — Verified (read in full, 66 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Terms not yet captured

AIRIN has not yet captured a gate-verified Terms of Service document for this platform.

Document status
  • Privacy Policy
    Verified - read in full - 66 citationsstaticLast captured 2026-08-21
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Training on your content

Discloses that third-party large-language-model providers are used via paid business API tiers and states that per those tiers' terms, data submitted to the API is not used to train the providers' public models — a protective restriction prohibiting training use of customer data by subprocessors, user-favorable in direction.

" Flowscope uses third-party large-language-model providers to generate workflow summaries, process analyses, and related outputs. We currently use OpenAI and may add or substitute other providers over time. We use paid business API tiers fr..."
📍 § 4 (Artificial intelligence)Jump to exact text →
plan language
Privacy & data use

This segment identifies the legal entity issuing the policy and defines the scope of the policy by describing what categories of activity it covers (collection, use, sharing, retention, and protection of personal information) and what rights data subjects have, establishing the foundational definitional framework for the entire document.

" This Privacy Policy is issued by GEO Advisor, Inc. , a Delaware corporation doing business as flowscope (“flowscope”, “we”, “us”, “our”). It describes how we collect, use, share, retain, and protect personal information, and what rights yo..."
📍 § 1 (Who we are)Jump to exact text →
plan language
Privacy & data use

This segment defines a second category of persons covered by the policy — employees of customers whose workplace activity is captured by the extension or desktop agent where authorized by their employer — scoping the policy's application to employer-authorized data capture scenarios.

" Employees of our customers whose business-application activity is captured by the flowscope Chrome extension or desktop agent, where that capture has been authorized by their employer."
📍 § 1 (Who we are)Jump to exact text →
plan language
Privacy & data use

This segment defines a third category of persons covered by the policy — those who contact the company, request demos, or otherwise interact with it in a business context — completing the scope definition.

" People who contact us, request a demo, or otherwise interact with us in a business context."
📍 § 1 (Who we are)Jump to exact text →
plan language
Privacy & data use

This segment defines the conditions and scope under which the extension or desktop agent collects data — employer installation and authorization are required — and identifies the type of data collected as business workflow events from employer-approved applications, establishing the lawful basis and scope of this collection category.

" When your employer installs the flowscope extension or desktop agent on your device and authorizes capture, we collect business workflow events generated while you use the applications your employer has approved. This can include:"
plan language
Privacy & data use

Defines a permitted purpose for which the company processes personal data — reconstructing and analyzing business workflows for enterprise customers to identify inefficiencies — establishing a lawful use of customer data.

" Reconstruct and analyze business workflows for our enterprise customers, so they can identify inefficiencies and opportunities for improvement."
📍 § 3 (How we use information)Jump to exact text →
plan language
Privacy & data use

Defines and enumerates the legal bases on which the company relies for processing personal data — contract performance, legitimate interests, consent, and legal obligation — and maps each to specific processing activities, serving as a foundational definitional clause for lawful processing grounds.

" Where required by law, we rely on the following legal bases: contract performance (providing the Services you or your employer have engaged us to provide), legitimate interests (product improvement, security, business administration), cons..."
📍 § 3 (How we use information)Jump to exact text →
plan language
Privacy & data use

Describes additional rights available to residents under named consumer privacy statutes, including the right to know categories of personal information collected, sources, purposes, and categories of third parties with whom it has been shared, and lists the specific categories collected such as identifiers, network activity information, and professional or employment-related information.

" California residents. Under the California Consumer Privacy Act and the California Privacy Rights Act, you have the rights listed above, plus the right to know the specific categories of personal information we have collected, the sources,..."
📍 § 9 (Your privacy rights)Jump to exact text →
Conflicting provisions (1)
  • Clause A states the identification service runs only after cookie acceptance, but Clause B describes methods like IP-to-organization matching which can operate independently of cookie consent, creating an opposing claim about when the service operates.

    " The current provider is named in the subprocessor list in Section 5. This service runs only after you accept analytics and identification cookies via our cookie banner. To withdraw consent, use the “Manage cookie preferences” control in our footer and choose Decline. To request a current opt-out URL, contact us at founders@flowscope.com ."
    " We use a third-party B2B visitor identification service to identify the organization associated with visitors to our website, and (for visitors located in the United States, where the service supports it) the individual professional contact associated with the visit. Such services typically perform identification using IP-to-organization matching, first-party cookies, and the provider’s identity graph drawn from cookies and accounts on partner websites. For visitors located outside the United States, identification is generally restricted to organization-level information and excludes personal data."
    Within one document

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 2
Tier-specific - 0
Total citations - 66
Severity
Surface
Document
Tier
Subprocessors & data sharing
High
" Service providers (subprocessors) who operate parts of our infrastructure under written contracts that restrict their use of personal information. The subprocessors that support this website are:"
§ 5 (How we share information)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

States that service providers acting as subprocessors operate under written contracts that restrict their use of personal information, establishing a contractual obligation governing how subprocessors may handle data.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" The subprocessors that process data captured through the flowscope product (cloud hosting, managed database, PII redaction, document text extraction, LLM inference, and transactional email) are maintained as a single, current list at trust.flowscope.com/subprocessors , which we update whenever those subprocessors change. Material additions will also be reflected in this Privacy Policy."
Privacy Policy › “Google LLC Google Analytics 4 (web analytics)”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes the procedure for maintaining and updating the list of product-level subprocessors, stating that the current list is kept at a specified URL and that material additions will be reflected in the Privacy Policy, establishing a transparency and update mechanism.

AI-generated interpretation, not legal advice.

Training on your content
High
" Flowscope uses third-party large-language-model providers to generate workflow summaries, process analyses, and related outputs. We currently use OpenAI and may add or substitute other providers over time. We use paid business API tiers from these providers. Per the applicable terms of these tiers, data submitted to the API is not used to train the providers’ public models. We will update this section to reflect material changes in our providers or the applicable terms."
§ 4 (Artificial intelligence)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Discloses that third-party large-language-model providers are used via paid business API tiers and states that per those tiers' terms, data submitted to the API is not used to train the providers' public models — a protective restriction prohibiting training use of customer data by subprocessors, user-favorable in direction.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" We do not sell or rent personal information. We do not share personal information for third-party cross-context behavioral advertising. We have not done so in the preceding twelve months and have no current plan to do so. "
Privacy Policy › “Google LLC Google Analytics 4 (web analytics)”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Expressly prohibits the sale or rental of personal information and prohibits sharing for third-party cross-context behavioral advertising, stating this has not occurred in the preceding twelve months and there is no current plan to do so — a user-favorable restriction on data sharing practices.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Field values where the employer’s configuration requires them for workflow reconstruction, subject to on-device redaction rules."
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This segment restricts collection of field values to cases where the employer's configuration requires them for workflow reconstruction and subjects such collection to on-device redaction rules, limiting the scope of field-level data capture.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Password values (browser APIs prevent this)."
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This segment states that password values are not collected, citing browser API limitations as the technical basis, functioning as a protective restriction on the categories of sensitive data captured.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" California residents. Under the California Consumer Privacy Act and the California Privacy Rights Act, you have the rights listed above, plus the right to know the specific categories of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we have shared it. The categories we collect are: identifiers (name, email, IP address, online identifiers); internet or other electronic network activity information (captured workflow events on employer-approved applications; website traffic); professional or employment-related information (company, role, work email); and inferences drawn from the above (derived workflow models). We do not sell or share personal information for cross-context behavioral advertising, so no “Do Not Sell or Share My Personal Information” link is required."
§ 9 (Your privacy rights)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes additional rights available to residents under named consumer privacy statutes, including the right to know categories of personal information collected, sources, purposes, and categories of third parties with whom it has been shared, and lists the specific categories collected such as identifiers, network activity information, and professional or employment-related information.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" The Services are intended for users who are at least 18 years old and who are using the Services in a business, employment, or similar professional context. We do not knowingly collect personal information from anyone under 18. If you become aware that a child’s personal information has been collected, please contact us and we will delete it."
§ 11 (Children)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Restricts the service to users at least 18 years old acting in a professional context, states the company does not knowingly collect personal information from anyone under 18, and establishes an obligation to delete such information if notified.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" We share personal information only as described below:"
§ 5 (How we share information)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

States that personal information is shared only as described below, imposing a general restriction limiting sharing to enumerated circumstances and establishing the scope of permissible disclosure.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Correction — ask us to correct inaccurate information."
§ 9 (Your privacy rights)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Grants users the right to request correction of inaccurate personal information held by the company.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Deletion — ask us to delete your personal information."
§ 9 (Your privacy rights)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Grants users the right to request deletion of their personal information.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" This Privacy Policy is issued by GEO Advisor, Inc. , a Delaware corporation doing business as flowscope (“flowscope”, “we”, “us”, “our”). It describes how we collect, use, share, retain, and protect personal information, and what rights you have."
§ 1 (Who we are)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This segment identifies the legal entity issuing the policy and defines the scope of the policy by describing what categories of activity it covers (collection, use, sharing, retention, and protection of personal information) and what rights data subjects have, establishing the foundational definitional framework for the entire document.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Employees of our customers whose business-application activity is captured by the flowscope Chrome extension or desktop agent, where that capture has been authorized by their employer."
§ 1 (Who we are)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This segment defines a second category of persons covered by the policy — employees of customers whose workplace activity is captured by the extension or desktop agent where authorized by their employer — scoping the policy's application to employer-authorized data capture scenarios.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" People who contact us, request a demo, or otherwise interact with us in a business context."
§ 1 (Who we are)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This segment defines a third category of persons covered by the policy — those who contact the company, request demos, or otherwise interact with it in a business context — completing the scope definition.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Contact details (name, email address, company, role) when you request a demo, sign up, or contact us."
§ 2.1 (Information you provide directly)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This segment identifies a specific category of personal information collected — contact details including name, email, company, and role — and the circumstances under which it is provided (requesting a demo, signing up, or contacting the company), establishing the scope of directly provided data collection.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Account authentication data when you register for product access."
§ 2.1 (Information you provide directly)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This segment identifies account authentication data as a category of personal information collected when a user registers for product access, defining what is collected in the registration context.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" When your employer installs the flowscope extension or desktop agent on your device and authorizes capture, we collect business workflow events generated while you use the applications your employer has approved. This can include:"
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This segment defines the conditions and scope under which the extension or desktop agent collects data — employer installation and authorization are required — and identifies the type of data collected as business workflow events from employer-approved applications, establishing the lawful basis and scope of this collection category.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Click, keyboard shortcuts (modifier and named keys, not raw typing), navigation, copy, and paste events on approved applications."
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

This segment enumerates specific interaction event types collected (clicks, keyboard shortcuts limited to modifier and named keys excluding raw typing, navigation, copy, and paste events on approved applications), defining the granular scope of behavioral data capture.

AI-generated interpretation, not legal advice.

Common questions about flowscope's policies

Does flowscope train its AI models on your data?
No training on your content by default — based on 1 verified finding from flowscope's published policy. Informational only, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from flowscope's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in flowscope's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in flowscope's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What flowscope requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in flowscope's published policies yet.

What the policies actually cover

0 topics

None of flowscope's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Cross-clause notes

Cross-reference

Two verified clauses intersect on the same subject matter: the Privacy Policy, § 6 (How long we keep information) addresses how long content is retained, and the Privacy Policy, § 4 (Artificial intelligence) addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.

Ambiguity — Caution

Verified retention clauses point in different directions: the Privacy Policy, § 6 (How long we keep information) describes broad or open-ended retention, while the Privacy Policy, § 6 (How long we keep information) describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.

Automated cross-reference against the published rubric — not legal advice.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

99
clauses
10
patterns
10
stances
privacy sharing · 8legal burden · 1training use · 1
legal burdenMEDIUM§ 3 (How we use information)

The clause requires defense, indemnity, or hold-harmless obligations.

Comply with legal obligations, enforce our agreements, and defend our legal rights.
Open source citation
privacy sharingHIGHPrivacy Policy › “Google LLC Google Analytics 4 (web analytics)”

The clause permits sale of personal data or information.

We do not sell or rent personal information. We do not share personal information for third-party cross-context behavioral advertising. We have not done so in the preceding twelve months and have no current plan to do so.
Open source citation
privacy sharingHIGH§ 9 (Your privacy rights)

The clause permits sale of personal data or information.

California residents. Under the California Consumer Privacy Act and the California Privacy Rights Act, you have the rights listed above, plus the right to know the specific categories of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we have shared it. The categories we collect are: identifiers (name, email, IP address, online identifiers); internet...
Open source citation
privacy sharingHIGHPrivacy Policy › “Google LLC Google Analytics 4 (web analytics)”

The clause permits sale of personal data or information.

We do not sell or rent personal information. We do not share personal information for third-party cross-context behavioral advertising. We have not done so in the preceding twelve months and have no current plan to do so.
Open source citation
privacy sharingHIGH§ 9 (Your privacy rights)

The clause permits sale of personal data or information.

California residents. Under the California Consumer Privacy Act and the California Privacy Rights Act, you have the rights listed above, plus the right to know the specific categories of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we have shared it. The categories we collect are: identifiers (name, email, IP address, online identifiers); internet...
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersindemnity liabilityconditionalMEDIUM1
All applicable tiersprivacy data useworsensHIGH3
All applicable tierssubprocessors data sharingworsensHIGH3
Pro / Paidprivacy data useworsensHIGH2
Pro / Paidtraining useimprovesLOW1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Aug 21, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

We do not sell or rent personal information. We do not share personal information for third-party cross-context behavioral advertising. We have not done so in the preceding twelve months and have no current plan to do so.
Open timeline citation
Aug 21, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

California residents. Under the California Consumer Privacy Act and the California Privacy Rights Act, you have the rights listed above, plus the right to know the specific categories of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we have shared it. The categories we collect are: identifiers (name, email, IP address, online identifiers); internet or other electronic network activity information (captured workflow events on employer-approved applications; website traffic); professional or employment-related information (company, role, work email); and inferences drawn from the above (derived workflow models). We do not sell or share personal information for cross-context behavioral advertising, so no “Do Not Sell or Share My Personal Information” link is required.
Open timeline citation
Aug 21, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

The subprocessors that process data captured through the flowscope product (cloud hosting, managed database, PII redaction, document text extraction, LLM inference, and transactional email) are maintained as a single, current list at trust.flowscope.com/subprocessors , which we update whenever those subprocessors change. Material additions will also be reflected in this Privacy Policy.
Open timeline citation
Aug 21, 2026legal burdenMEDIUM

Latest stance: indemnity on indemnity liability

Comply with legal obligations, enforce our agreements, and defend our legal rights.
Open timeline citation
Aug 21, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

Service providers (subprocessors) who operate parts of our infrastructure under written contracts that restrict their use of personal information. The subprocessors that support this website are:
Open timeline citation
Jul 20, 2026model trainingLOW

Latest stance: no training claim on training use

Flowscope uses third-party large-language-model providers to generate workflow summaries, process analyses, and related outputs. We currently use OpenAI and may add or substitute other providers over time. We use paid business API tiers from these providers. Per the applicable terms of these tiers, data submitted to the API is not used to train the providers’ public models. We will update this section to reflect material changes in our providers or the applicable terms.
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

Service providers (subprocessors) who operate parts of our infrastructure under written contracts that restrict their use of personal information. The subprocessors that support this website are:
Open timeline citation
Jul 20, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

The subprocessors that process data captured through the flowscope product (cloud hosting, managed database, PII redaction, document text extraction, LLM inference, and transactional email) are maintained as a single, current list at trust.flowscope.com/subprocessors , which we update whenever those subprocessors change. Material additions will also be reflected in this Privacy Policy.
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-08-21· verified 2026-08-21

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

99 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of flowscope's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified flowscope's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from flowscope's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.